GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,325 advisories
Filter by severity
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations
Moderate
CVE-2026-53442
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"
Moderate
CVE-2026-53440
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Jenkins exposes other users' timezone and view names to users with Overall/Read permission
Moderate
CVE-2026-53439
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Jenkins: Missing permission check allows unauthorized cancellation of queue items
Moderate
CVE-2026-53438
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL
Moderate
CVE-2026-53437
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Moderate
CVE-2026-64607
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Jul 31, 2026
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
Moderate
CVE-2026-49844
was published
for
org.apache.logging.log4j:log4j-api
(Maven)
Jul 11, 2026
Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL
Moderate
CVE-2026-53436
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
Moderate
CVE-2026-48043
was published
for
io.netty:netty-codec-http2
(Maven)
Jun 11, 2026
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Moderate
CVE-2026-73508
was published
for
io.netty:netty-codec-dns
(Maven)
Jul 24, 2026
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution
Moderate
CVE-2026-53914
was published
for
org.jetbrains.kotlin:kotlin-gradle-plugin
(Maven)
Jun 26, 2026
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
Moderate
CVE-2026-41721
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jun 10, 2026
Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation
Moderate
CVE-2026-41727
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
Spring Data REST potentially exposes persistence-layer internals to HTTP clients
Moderate
CVE-2026-41730
was published
for
org.springframework.data:spring-data-rest-core
(Maven)
Jun 10, 2026
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations
Moderate
CVE-2026-41837
was published
for
org.springframework.data:spring-data-rest-core
(Maven)
Jun 10, 2026
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter
Moderate
CVE-2026-41008
was published
for
org.springframework.security:spring-security-oauth2-authorization-server
(Maven)
Jun 10, 2026
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
Moderate
CVE-2026-41701
was published
for
org.springframework.amqp:spring-amqp
(Maven)
Jun 10, 2026
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods
Moderate
CVE-2026-41696
was published
for
org.springframework.data:spring-data-mongodb
(Maven)
Jun 10, 2026
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference
Moderate
CVE-2026-41697
was published
for
org.springframework.data:spring-data-relational
(Maven)
Jun 10, 2026
Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache
Moderate
CVE-2026-41706
was published
for
org.springframework.security:spring-security-web
(Maven)
Jun 10, 2026
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
Moderate
CVE-2026-41711
was published
for
org.springframework.data:spring-data-commons
(Maven)
Jun 10, 2026
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean
Moderate
CVE-2026-41714
was published
for
org.springframework.amqp:spring-amqp
(Maven)
Jun 10, 2026
Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries
Moderate
CVE-2026-41719
was published
for
org.springframework.data:spring-data-keyvalue
(Maven)
Jun 10, 2026
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference
Moderate
CVE-2026-40991
was published
for
org.springframework.restdocs:spring-restdocs-restassured
(Maven)
Jun 10, 2026
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Moderate
CVE-2026-56818
was published
for
io.netty:netty-codec-redis
(Maven)
Aug 7, 2026
ProTip!
Advisories are also available from the
GraphQL API